1. About this policy
This policy explains the cookies and similar technologies used on thecookieproject.co.uk. It should be read with our Privacy Policy, which explains how we handle personal information more generally.
Our use of cookies is governed by the Privacy and Electronic Communications Regulations 2003 (PECR). Where cookie information identifies or can be linked to an individual, UK data protection law also applies.
2. What cookies and similar technologies are
A cookie is a small text file stored on a browser or device. Cookies may last only for a browsing session or remain until a stated expiry date. First-party cookies are set by our website; third-party cookies are set by another service used on the website.
We may also use local storage, session storage, pixels or similar browser technologies. PECR can apply to these in the same way as cookies, so references to “cookies” in this policy include similar technologies where appropriate.
3. Consent and cookie categories
We use strictly necessary cookies without consent where they are essential to provide a service you request, secure the website, remember your cookie choice, operate the basket or checkout, authenticate an account, or prevent payment fraud.
We ask for consent before setting cookies used for optional analytics, marketing or non-essential functionality. Rejecting optional cookies must be as easy as accepting them, and you can change your mind at any time using the Re-consent control displayed on the website.
Consent is specific to the browser and device you use. Clearing cookies may also clear your recorded choice, so the banner may appear again.
4. Strictly necessary and preference cookies
The current website stack may use the following core cookies. Asterisks indicate a variable suffix used to keep identifiers unique.
| Cookie or storage key | Provider | Purpose | Typical duration |
|---|---|---|---|
cookieadmin_consent | The Cookie Project / CookieAdmin | Records cookie categories accepted or rejected and the associated consent record. | 365 days |
woocommerce_cart_hash | WooCommerce | Detects changes to the shopping basket. | Session |
woocommerce_items_in_cart | WooCommerce | Remembers whether the basket contains products. | Session |
wp_woocommerce_session_* | WooCommerce | Links a visitor to their basket and checkout session without storing card details. | Normally 2 days |
wc_cart_hash_* and wc_fragments_* | WooCommerce | Local or session storage used to keep basket content and totals up to date. | Session or about 1 day |
tcp_wishlist | The Cookie Project | Remembers saved cookie cutters for visitors who are not signed into an account. | 1 year |
wordpress_logged_in_*, wordpress_sec_* and related WordPress authentication cookies | WordPress | Authenticates signed-in users and protects account sessions. | Session, or up to 14 days where “remember me” is used |
wordpress_test_cookie | WordPress | Checks whether the browser accepts cookies on login and account screens. | Session |
tcp_store_preview | The Cookie Project | Allows an authorised reviewer to bypass the Coming Soon page. It is not set for ordinary visitors. | 7 days |
Cookie lifetimes can be shorter where you close the browser, sign out, clear storage or withdraw consent.
5. Optional analytics and order-attribution cookies
We do not currently intend to run general advertising or social-media tracking cookies. If optional analytics or campaign measurement is enabled, it will be blocked until the relevant consent is given and the consent tool will describe the category.
WooCommerce may use Sourcebuster keys such as sbjs_current, sbjs_first, sbjs_udata, sbjs_migrations and related variants to understand how an order reached the store. These normally last up to six months; sbjs_session normally lasts about 30 minutes. Where these are not strictly necessary, they will be treated as optional and controlled through consent.
If we later add a new analytics, advertising or embedded-media service, we will update the consent categories and this policy before using its non-essential cookies.
6. Stripe payment and fraud-prevention cookies
When Stripe payment functions are active, Stripe.js may set cookies and similar technologies needed to process and authenticate payments and reduce fraud. Stripe states that these can include:
| Cookie | Purpose | Typical duration |
|---|---|---|
__stripe_mid | Fraud prevention and distinguishing legitimate payment activity from abusive activity. | 1 year |
__stripe_sid | Fraud prevention during a payment session. | 30 minutes |
m | Fraud detection and risk assessment. | Up to 2 years |
pay_sid, __Host-LinkSession or related Link keys | Authentication and remembering an optional Stripe Link checkout session where that feature is used. | Depends on the Stripe feature; authentication may be remembered for up to 90 days |
Stripe controls these technologies and may change them as its service develops. Fraud-prevention cookies may be treated as necessary for secure payment processing. Optional Stripe features remain subject to the appropriate consent controls. See Stripe’s Privacy Center and Stripe’s cookie information.
7. Third-party services
Some functions involve another organisation, such as Stripe for payments or Royal Mail links for tracking. A third party may set cookies on its own website after you follow a link. Its cookie and privacy terms will apply there.
We do not control browser storage set entirely on another organisation’s domain, but we select providers with care and keep our disclosures under review.
8. How to manage cookies
You can use the website’s cookie banner or Re-consent control to accept, reject or change optional categories. Withdrawing consent does not affect processing that took place before withdrawal.
You can also block or delete cookies through browser settings. Blocking strictly necessary cookies may prevent the basket, checkout, account, wishlist or security features from working properly. Browser help pages explain how to manage cookies, local storage and site data.
Signals such as Global Privacy Control may also be honoured where supported by the relevant service. Cookie choices made on one browser or device do not automatically carry across to another.
9. Contact and policy changes
For questions about cookies or consent records, email [email protected] or write to Kendall Group Ltd, 51 Birch Grove, Mansfield, England, NG18 4JH.
We review this policy when the website, plugins, payment tools or legal requirements change. Because providers can update cookie names and durations, the consent panel shown on the website should be read alongside this page.
Last updated: 26 August 2026